Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

EC-Council Certified Security Analyst (ECSA) v10 : Penetration Testing

Last Update 4 hours ago Total Questions : 201

The EC-Council Certified Security Analyst (ECSA) v10 : Penetration Testing content is now fully updated, with all current exam questions added 4 hours ago. Deciding to include ECSAv10 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our ECSAv10 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these ECSAv10 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any EC-Council Certified Security Analyst (ECSA) v10 : Penetration Testing practice test comfortably within the allotted time.

Question # 51

Attackers create secret accounts and gain illegal access to resources using backdoor while bypassing the authentication procedures. Creating a backdoor is a where an attacker obtains remote access to a computer on a network.

Which of the following techniques do attackers use to create backdoors to covertly gather critical information about a target machine?

A.

Internal network mapping to map the internal network of the target machine

B.

Port scanning to determine what ports are open or in use on the target machine

C.

Sniffing to monitor all the incoming and outgoing network traffic

D.

Social engineering and spear phishing attacks to install malicious programs on the target machine

Question # 52

Amazon, an IT based company, conducts a survey on the usage of the Internet. They found that company employees spend most of the time at work surfing the web for their pe rsonal use and for inappropriate web site viewing. Management decide to block all such web sites using URL filtering software.

How can employees continue to see the blocked websites?

A.

Using session hijacking

B.

Using proxy servers

C.

Using authentication

D.

Using encryption

Question # 53

A pen tester has extracted a database name by using a blind SQL injection. Now he begins to test the table inside the database using the below query and finds the table:

http://juggyboy.com/page.aspx?id=1; IF (LEN(SELECT TOP 1 NAME from sysobjects where xtype= ' U ' )=3) WAITFOR DELAY ' 00:00:10 ' --

http://juggyboy.com/page.a spx?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),1,1)))=101) WAITFOR DELAY ' 00:00:10 ' --

http://juggyboy.com/page.aspx?id=1; IF (ASCII(lower(substring((SELECT T OP 1 NAME from sysobjects where xtype=char(85)),2,1)))=109) WAITFOR DELAY ' 00:00:10 ' --

http://juggyboy.com/page.aspx?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85 )),3,1)))=112) WAITFOR DELAY ' 00:00:10 ' —

What is the table name?

A.

CTS

B.

QRT

C.

EMP

D.

ABC

Question # 54

Which one of the following is a supporting tool for 802.11 (wireless) packet injections, it spoofs 802.11 packets to verify whether the access point is valid or not?

A.

Airsnort

B.

Aircrack

C.

Airpwn

D.

WEPCrack

Question # 55

Which of the following contents of a pen testing project plan addresses the strengths, weaknesses, opportunities, and threats involved in the project?

A.

Project Goal

B.

Success Factors

C.

Objectives

D.

Assumptions

Question # 56

Which of the following are the default ports used by NetBIOS service?

A.

135, 136, 139, 445

B.

134, 135, 136, 137

C.

137, 138, 139, 140

D.

133, 134, 139, 142

Question # 57

Which of the following is a framework of open standards developed by the Internet Engineering T ask Force (IETF) that provides secure transmission of the sensitive data over an unprotected medium, such as the Internet?

A.

DNSSEC

B.

Netsec

C.

IKE

D.

IPsec

Question # 58

John, a penetration tester from a pen test firm, was asked to collect information about the host file in a Windows system directory. Which of the following is the location of the host file in Window system directory?

A.

C:\Windows\System32\Boot

B.

C:\WINNT\system32\drivers\etc

C.

C:\WINDOWS\system32\cmd.exe

D.

C:\Windows\System32\restore

Question # 59

Identify the type of testing that is carried out without giving any information to the employees or administrative head of the organization.

A.

Unannounced Testing

B.

Double Blind Testing

C.

Announced Testing

D.

Blind Testing

Question # 60

A framework is a fundamental structure used to support and resolve complex issues. The framework that delivers an efficient set of technologies in order to develop applications which are more secure in using Internet and Intranet is:

A.

Microsoft Internet Security Framework

B.

Information System Security Assessment Framework (ISSAF)

C.

Bell Labs Network Security Framework

D.

The IBM Security Framework

Go to page: